Re: PHP 4.0 Bug #6660: PHP magic variables can be overridden by GPC variables
| From: | Jon Ribbens | Date: | Mon, 11 Sep 2000 12:51:36 +0000 |
| Subject: | Re: PHP 4.0 Bug #6660: PHP magic variables can be overridden by GPC variables | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32903@lists.php.net to get a copy of this message | ||
jon+php-dev@unequivocal.co.uk wrote:
> If register_globals is on, then PHP magic variables (HTTP_GET_VARS,
> HTTP_POST_VARS, etc) can be faked by remote web users. This is particularly
> important in the case of HTTP_ENV_VARS and HTTP_POST_FILES, which the script
> author may expect to come from a local source.
Hmm, actually, 4.0.3RC1 seems to improve this. I am not sure what has
changed though, so I can't check for sure.
I would put this in the bug system, but it has changed again so I cannot.
(It is asking me for a username and password.)